Null Pointer Dereference in Lenovo Power Management Driver for Windows 10
CVE-2021-3463

4.2MEDIUM

Key Information:

Vendor
Lenovo
Vendor
CVE Published:
13 April 2021

Summary

The Lenovo Power Management Driver for Windows 10 contains a null pointer dereference vulnerability that may lead to a system crash, resulting in a blue screen error. This issue affects versions prior to 1.67.17.54, posing a significant risk for users who have not updated the driver. It highlights the importance of keeping software up to date to maintain system stability and security.

Affected Version(s)

Power Management Driver for Windows 10 < 1.67.17.54

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lenovo thanks Aobo Wang of Chaitin Security Research Lab for reporting these issues.
.